
mz3z2 (mz3z2) asked a question.
We have a number of users who access an application from Okta but need connect/access the app with their credentials from a terminal and not a gui, so when prompted for MFA they can't enter details of course and login. Is it possible to bypass MFA just for this app when MFA is enabled by default at organisation level? e.g. users login to other apps still need MFA prompted.

Hello @mz3z2 (mz3z2),
Yes, you can add a rule to exclude the users from the MFA policy. Even if the MFA is enabled at the organization level. Just to your MFA policy & Add a rule to exclude the users from MFA. It should work.
If you need additional information or assistance you can use the link below as a reference to reach our helpdesk team and get further assistance with your scenario:
https://help.okta.com/en/prod/Content/Topics/Directory/get-support.htm
Have a great day ahead.
Regards,
Natalia
Okta Inc.
You could exclude them from the org-level MFA sign-on rule and then prompt them for MFA in a sign-on rule at the application level, although you'd have to create the same sign-on rule on every app they use (other than the one they access from the terminal).
I would think that when dealing with a Service Provider Initiated (SP-initiated) SSO workflow Okta could see the originating app and let you set a different policy (non-MFA) for the user and just do simple authentication.